RVAsec 13 Speaker Feature: Evan Booth

Evan Booth is a builder and architect at Counter Hack, a company devoted to building fun and engaging challenges that educate and evaluate information security professionals. Armed with a profound fascination with how things are built, Evan has spent the past 20 years working on the creative, strategic, and engineering components of software and hardware projects for a wide variety of clients. Evan enjoys spending time with his family, taking stuff apart, and occasionally putting stuff back together again. X (Twitter): @evanbooth

Scaling Your Creative Output with AI: Lessons from SANS Holiday Hack Challenge 2023 (<– add to your schedule)

The rise in prominence of AI-powered content generation tools over the past year was tough to miss, and, heck, you have probably already created some cool stuff with them. Putting these tools to work in a meaningful, scalable way, however, can prove challenging.

In this talk, I will equip you with the technical knowledge required to build AI-enhanced tools, we’ll discuss strategies for identifying opportunities for said tools, and we’ll look at real-world examples from SANS Holiday Hack Challenge, the best darn free, seasonal hacking challenge in the world.

Come see Evan Booth at RVAsec 13!


RVAsec 13 Speaker Feature: Caleb Gross / Josh Shomo

Caleb Gross is the Director of Capability Development at Bishop Fox, where he leads a team of offensive security professionals specializing in attack surface research and vulnerability intelligence. Prior to coming to Bishop Fox, he served as an exploitation operator in the US Department of Defense’s most elite computer network exploitation (CNE) unit. As a top-rated military officer, Caleb led an offensive operations team in the US Air Force’s premier selectively manned cyber attack squadron. He studied at the University of Virginia and holds two degrees in computer science.

Josh Shomo leads the vulnerability research team within Bishop Fox’s Capability Development group. He investigates security issues in widely used applications and appliances, and produces vulnerability intelligence to prioritize offensive security research at Bishop Fox. Josh earned a master’s degree in computer science from Johns Hopkins University. Before joining Bishop Fox, Josh attended the Computer Network Operations Development Program (CNODP), the US Department of Defense’s foremost vehicle for developing technical leaders in information security. X (Twitter): @noperator

Patch Perfect: Harmonizing with LLMs to Find Security Vulns (<– add to your schedule)

Are LLMs a revolutionary leap forward for security research—or just spicy auto-complete?

The truth lies somewhere in between. This talk cuts through the hype and offers a practical perspective that’s grounded in real-world analysis of critical bugs in widely used products. We’ll walk through our process of harnessing large language models (LLMs) for patch-diffing in the context of N-day vulnerability research. Given a vague security advisory and some complicated code diffs, can an LLM get you closer to finding the right spot in the code to dig deeper? Which models work best for this task, and why? Let’s ditch the theory and get our hands dirty with iterative experimentation. Whether you’re a seasoned pentester, applied researcher, or budding practitioner, you’ll take away tactical lessons for incorporating AI into your security toolkit.

Come see Caleb Gross at RVAsec 13!


RVAsec 13 Speaker Feature: Jimi Sebree / Evan Grant

Evan Grant is based out of Halifax, Nova Scotia and works as a Security Researcher at Tenable. He got his start in infosec working with the Canadian Forces Reserves, and has been hooked ever since. Outside of work, he occasionally tries to climb rocks, at which he is definitely worse than Jimi.

Jimi Sebree is security researcher on Tenable’s Research team. With a strong background in software engineering and security, he bounces between research disciplines in an effort to appear knowledgeable about a variety of topics. Occasionally he succeeds in tricking someone into listening to his ramblings. X (Twitter): @dinobytes / @stargravy

Consumer Routers Still Suck (<– add to your schedule)

You know that little box in the corner of your house doing all the heavy lifting required to connect you (and, now that everyone is working from home, your company) with the rest of the world? Yeah, that one. It’s no secret that these things are oftentimes security nightmares for consumers, but have ISPs or the various networking vendors improved things over the years, or are they still just as terrible as we all think they are?

Over the last few years, we’ve done a deep dive into many of these devices to see what makes them tick and evaluate the risks posed to consumers. In this talk, we’ll provide a rapid fire assessment of a handful of these devices, showcase the commonalities between flaws discovered, shed some light on behind-the-scenes supply chain issues plaguing this industry, and discuss where we see things going from here.

Come see Jimi Sebree / Evan Grant at RVAsec 13!


RVAsec 13 Speaker Feature: Kevin Johnson

Kevin Johnson is the Chief Executive Officer of Secure Ideas. Kevin has a long history in the IT field including system administration, network architecture and application development. He has been involved in building incident response and forensic teams, architecting security solutions for large enterprises and penetration testing everything from government agencies to Fortune 100 companies. In addition, Kevin is a faculty member at IANS and was an instructor and author for the SANS Institute. X (Twitter): @secureideas

Orion’s Quest: Navigating the Cyber Wilderness – Tales of Modern Penetration Testing (<– add to your schedule)

Focusing on real stories from the trenches, Orion’s Quest walks through a series of modern application and API attacks Kevin and his team have pulled off. The talk describes how we found and exploited the flaws and provides information so you can test yourself.

Come see Kevin Johnson at RVAsec 13!


ePlus – RVAsec 13 Gold Sponsor

RVAsec is pleased to present ePlus as an RVAsec 13 Gold sponsor!

From Cloud and Data Center, Security, Collaboration, Networking and AI, to Digital Transformation, Managed and Professional Services or Financing, we bring a vast perspective that helps organizations design, orchestrate and seamlessly implement versatile technology solutions.

https://www.eplus.com/
X (Twitter): @ePlus

RVAsec 13 tickets are available now!


RVAsec 13 Speaker Feature: David J. Bianco

David is a Staff Security Strategist on Splunk’s SURGe research team. He is also a SANS Certified Instructor, where he teaches network forensics. David has more than 20 years of experience in the information security field, primarily in incident detection and response, threat hunting, and Cyber Threat Intelligence (CTI). He is the creator of both the Pyramid of Pain and the Threat Hunting Maturity Model, both widely cited defensive security models. Really, he just wants to make security better for everyone, and he has a special interest in helping people get started in their cybersecurity careers. You can follow David on Twitter as @DavidJBianco or on Mastodon as @DavidJBianco@infosec.exchange. X (Twitter): @DavidJBianco

My Way is Not Very Sportsman-Like: Shaping Adversary Behavior to Strengthen Defenses (<– add to your schedule)

We’re taking a fresh look at how to beat cyber attackers at their own games! It’s all about using our defender advantages wisely, controlling, constraining, and shaping the adversary’s moves before the attack even begins. We’re ditching the old “”Defender’s Dilemma”” mindset and showing how smart defense strategies can make a huge difference. Let’s shift our thinking, use our advantages better, and boost our defense without breaking the bank.

Come see David J. Bianco at RVAsec 13!


Simeio Solutions – RVAsec 13 Gold Sponsor

RVAsec is pleased to present Simeio Solutions, LLC as an RVAsec 13 Gold sponsor!

We execute, manage, and optimize your entire Identity and Access Management (IAM) program. With a team of experts specialized in identity management, we are protecting more than 160 MN identities and leading our client’s digital transformation journey securely.

https://simeio.com/
X (Twitter): @Simeio

RVAsec 13 tickets are available now!


RVAsec 13 After Party — Casino Night — Register Now!

We typically like to rotate our after party events, but back by popular demand we will again have our exhilarating Casino Night! This spectacular event begins immediately after the last talk on Tuesday (day 1), running from 5:30pm to 9:00pm. Step into a lively atmosphere reminiscent of Las Vegas, right here in Richmond.

The RVAsec 13 after party, brought to you by RVAsec (still looking for a sponsor to make it even more epic!), will be at in the main ballroom on Tuesday, June 4th right after the conference ends!

  • 5:00pm to 9pm: Food/Beverage/Music
  • 5:30ish: Let the games begin!
  • 8:30ish: Games close and we will announce winners!

We’ve curated an array of classic casino games for your enjoyment. Roll the dice at the Craps table, or give our Roulette wheel a spin. If cards are more your speed, try a hand at our Black Jack table, or go all-in with Texas Hold ‘Em Poker. We also offer the exciting Texas Hold ‘Em Bonus Poker Table for a thrilling twist.

But it’s not all dice and cards – test your accuracy with our Golf Shot game, or back a winner with River City Horse Racing. And the best part? There will be food, beverages, music, and fabulous prizes for the top players!

So whether you’re a gaming veteran or a novice, this is your chance to relax, have fun, network, and possibly win big! As the day’s talks wrap up, prepare to immerse yourself in an unforgettable evening at the RVAsec after party!

Let the best players win!

This is an exclusive event, so you must be registered to attend or you will not be allowed entrance–no exceptions!

Important Notes:

  • You must use the same email you used to register for RVAsec.
  • Each attendee must have their own name listed (duplicates will be deleted).
  • If you are not registered for RVAsec, your ticket will be deleted. 
  • Age Restriction: You must be 21 and over to drink alcohol. Non-alcoholic beverages will be available.

Even if you have a ticket for RVAsec and said that you wanted to attend during the signup process, you MUST now registered for the party!

Register For The After Party Now!

If you haven’t bought a ticket for the RVAsec conference yet, now is the time…. click this link, you know you want to!

Or if you know better, don’t click that link, copy and paste this (https://www.eventbrite.com/e/rvasec-13-security-conference-tickets-776407274057) in and get that ticket!


RVAsec 13 Speaker Feature: Tucker Mahan

Tucker Mahan currently leads emerging technology initiatives at MAXX Potential, expanding capabilities and coaching others to build careers in technology.

He is a lifelong learner with a passion for all things Technology, and loves to share his ever-evolving knowledge on the subject. When he’s not helping others learn the fundamentals, he’s actively involved in many community and personal passion projects.

Trained in qualitative and quantitative data analysis to recognize trends and patterns
MicroMasters from The Georgia Institute of Technology in Analytics: Essential Tools and Methods
MAXX Potential Distinguished Alumni
VCU, BSc Sociology, minor in Math & Religious Studies

Defending Against the Deep: Is your workforce ready for Generative AI Adversaries? (<– add to your schedule)

Gain insight into the evolving landscape of cybersecurity in the age of AI Generated Content. From defending against multi-vector cyber attacks to empowering your workforce through AI-powered cybersecurity awareness, Defending Against the Deep delves into the intricacies of Generative AI. Together, we will look at case studies, a technical demonstration of current capabilities, keys for leveling up your workforce, and an opportunity to test your ability to recognize AI Generated Content. In this talk, explore how the same technology used for malicious intent can be harnessed for good, offering innovative solutions to safeguard enterprise environments.

Come see Tucker Mahan at RVAsec 13!


RVAsec 13 Speaker Feature: Aqeel Yaseen

Aqeel Yaseen transitioned into Offensive Security from over a decade of teaching yoga professionally, and is currently working with Blue Bastion Security. That might seem like a curious combination, but Pentesting and teaching yoga both help people cultivate awareness of blind spots, and find ways to learn and grow from that awareness. Aqeel has been teaching himself that art and skill of hacking by creating home labs, owning machines on HTB and Offsec’s Proving Grounds, and participating in CTFs. He has already earned the Security+, OSCP, and OSWA certifications, and is currently working towards the CRTO. He also has a website with two years of recorded yoga and meditation classes that are available for free. He is eager to learn and to share!

Mindfulness, Meditation, and Cybersecurity (<– add to your schedule)

We are meant to enjoy our lives; both personal, and professional.
As human beings, and as professionals, we all have to learn how to cultivate even-mindedness, balance, and fortitude to meet life/work challenges. Cybersecurity is fascinating because it requires us to constantly learn, and find ways to optimize our process. Burnout is a huge problem many fields, but especially in Cybersecurity. Cultivating a mindfulness or meditation practice is one of the most efficient ways we can support our process, and manage the stress and anxiety that comes with our professional and personal lives.

The focus of this talk is not specifically on work, because it addresses thoughtful ways to approach every aspect of our lives from our mental and physical health, to our relationships both personally and professionally. Whether new to the industry or a seasoned veteran, this talk with give you some insights, guidance, and the opportunity to practice.

Come see Aqeel Yaseen at RVAsec 13!